<div dir="ltr"><div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)"><pre>Thanks for your comments.<br><br>1. "Out of curiosity, how do you do this? I thought once a login handler was chosen you can't just invoke another one (e.g. from a JSP)?"<br>
</pre><pre>-> Kerberos Login Handler sets "krbLoginFailed" attribute if Kerberos authentication fails. Based on the "krbLoginFailed" attribute we forward the request to user-password login jsp.<br><br>
2. "Shouldn't you be able to configure the Kerberos Login Handler in a way that it will not automatically attempt SPNEGO with Kerberos rightaway, but only on request of the subject?"<br></pre><pre>-> We don't want to introduce additional click for all users to achieve some exceptional cases... so far we have requested users to access the resource using a browser that is not configured for kerberos. However we want a solution where users won't have to fiddle with browser setting to directly use user/password authentication.<br>
<br></pre><pre>Pls let me know if there are any other suggestions. <br></pre></div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Sun, Feb 2, 2014 at 12:48 PM, Vishvjit Khalipe <span dir="ltr"><<a href="mailto:vishvjit@gmail.com" target="_blank">vishvjit@gmail.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)">Hello,<br><br></div>
<div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)">We are using Shibboleth IdP 2.3.6 + Kerberos Login Handler + user password login as fail-over to enable SSO for users.<br>
<br></div><div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)">For all the relying parties we have Kerberos Login Handler as the Default Login Handler (defaultAuthenticationMethod). If kerberos authentication fails the user is redirected to user password login handler. So far, all the SP have requested unsolicited (IdP initialized) SSO.<br>
<br></div><div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)">However, in some cases (where a user wants to login from another users computer) we want to bypass the (defaultAuthenticationMethod) Kerberos Login Handler and go directly to User Password page. Is there any out of box config for this ?<br>
<br></div><div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)">Thank you in advance for your time and help.<span class="HOEnZb"><font color="#888888"><br clear="all"></font></span></div><span class="HOEnZb"><font color="#888888"><br>
-- <br><span style="color:rgb(0,0,102);font-family:trebuchet ms,sans-serif">Regards,</span><br style="color:rgb(0,0,102);font-family:trebuchet ms,sans-serif">
<span style="color:rgb(51,0,153);font-family:trebuchet ms,sans-serif"><span style="color:rgb(0,0,102)"> Vish</span><br style="color:rgb(0,0,102)"><br></span>
</font></span></div>
</blockquote></div><br><br clear="all"><br>-- <br><span style="color:rgb(0,0,102);font-family:trebuchet ms,sans-serif">Regards,</span><br style="color:rgb(0,0,102);font-family:trebuchet ms,sans-serif"><span style="color:rgb(51,0,153);font-family:trebuchet ms,sans-serif"><span style="color:rgb(0,0,102)"> Vish</span><br style="color:rgb(0,0,102)">
<br style="color:rgb(0,0,102)"><span style="color:rgb(0,0,102)">Vishvjit Khalipe</span><br><br></span>
</div>